HashiCorp Vault
HashiCorp Vault is a service that controls access to secrets such as passwords, API keys, certificates, and encryption keys. It authenticates people and applications, applies access policies, and can create short-lived credentials instead of distributing permanent ones.
itIdentity, access, and cryptography | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - HashiCorp Vault
HashiCorp Vault centers on Vault. Applications need credentials, certificates, and encryption keys. Copying those secrets into configuration files or deployment systems creates many uncontrolled copies.
Operate from the project's own resources and APIs. Learn how desired state becomes running state, which status conditions matter, and which dependencies (network, storage, identity, certificates) the control plane assumes.
Upgrades, backups, and credential rotation are part of the product, not optional aftercare. Version skew between clients and servers creates failures that look like application bugs. Pin versions and rehearse rollback.
Convenience features reduce boilerplate and widen blast radius. Enable them when you can observe and reverse the expanded surface. Defaults from quickstarts are starting points, not production policy.
Name owners for upgrades, credentials, and disaster recovery before traffic arrives. Unowned control-plane state becomes an outage with no clear pager. Prefer explicit version pins and tested rollback over floating tags that quietly change behavior between deploys.
Name owners for upgrades, credentials, and disaster recovery before traffic arrives. Unowned control-plane state becomes an outage with no clear pager. Prefer explicit version pins and tested rollback over floating tags that quietly change behavior between deploys.
Name owners for upgrades, credentials, and disaster recovery before traffic arrives. Unowned control-plane state becomes an outage with no clear pager. Prefer explicit version pins and tested rollback over floating tags that quietly change behavior between deploys.
Read the Intro for the mental model. Use the Cheatsheet when you need the resource map. Updates and Upstream track the Vault release line that changes these APIs.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://developer.hashicorp.com/vault/docs
Supports
- Vault purpose and major use cases
- Static secrets, dynamic credentials, certificates, identity, encryption, and compliance orientation
- https://developer.hashicorp.com/vault/docs/about-vault/how-vault-works
Supports
- Identity-based secrets and encryption management
- Client, auth method, token, policy, core, secrets engine, lease, barrier, seal, and audit request flow
- Shamir unseal and auto-unseal overview
- https://developer.hashicorp.com/vault/docs/about-vault/what-is-vault
Supports
- Secret examples and centralized privileged access
- Self-managed and managed offering context
- https://developer.hashicorp.com/vault/docs/auth
Supports
- Auth methods verify clients and associate policies
- External identity delegation and mounted auth paths
- https://developer.hashicorp.com/vault/docs/concepts/policies
Supports
- Path-based authorization and capabilities
- Deny-by-default behavior
- https://developer.hashicorp.com/vault/docs/secrets
Supports
- Secrets engines store, generate, or encrypt data
- Engines mount at paths and remain isolated through barrier views
- https://developer.hashicorp.com/vault/docs/secrets/databases
Supports
- Dynamic database credential generation and revocation
- https://developer.hashicorp.com/vault/docs/concepts/lease
Supports
- Lease identifiers, time to live, renewal, expiry, and revocation
- Token revocation cascades to leases created through that token
- Key-value secrets are not dynamic leased credentials
- https://developer.hashicorp.com/vault/docs/audit
Supports
- Requests and responses pass through configured audit devices
- At least one enabled audit device must accept a record
- Audit destination failures can affect request availability
- https://developer.hashicorp.com/vault/docs/internals/integrated-storage
Supports
- Integrated Storage uses Raft and replicates Vault data
- Snapshot and recovery responsibilities
- https://developer.hashicorp.com/vault/docs/configuration/storage
Supports
- Integrated Storage recommendation for most use cases
- https://developer.hashicorp.com/vault/docs/internals/high-availability
Supports
- One active node and hot standby nodes
- Standby redirection, failover, and requirement that standby nodes be unsealed
- https://developer.hashicorp.com/vault/docs/deploy
Supports
- Production deployment and operational planning topics
- https://developer.hashicorp.com/vault/tutorials/get-started
Supports
- Guided foundation path covering setup, secrets, tokens, auth methods, and policies
- https://github.com/sindresorhus/awesome
Supports
- Discovery path to curated security and DevOps awesome lists
- https://github.com/wmariuss/awesome-devops
Supports
- Vault Secrets Operator as a curated secret-management ecosystem entry
- https://github.com/sbilly/awesome-security
Supports
- Teller as a curated DevOps secret-management tool
- https://developer.hashicorp.com/vault/docs/deploy/kubernetes/vso
Supports
- Supported operator status
- Kubernetes custom resources and synchronization to Kubernetes Secrets
- https://github.com/tellerops/teller
Supports
- HashiCorp Vault provider
- Process injection, secret scanning, output redaction, and multi-provider operation
